πŸš€ Submit a Challenge β€” SecDim AppSec Village CTF at DEF CON 34 and Win a ROG Xbox Ally

DAO and Recursive Calls

1hIntermediateSolidity

In June 2016, The DAO, a crowd-funding contract, was compromised and resulted in a loss of 3.6 million Ether ($50M at the time of the attack). Let's explore what happened and why, and how to protect our smart contracts against this vulnerability.

Topics

  1. Introduction

    Lesson10m

    The DAO, a crowd-funding contract, was compromised due to multiple vulnerabilities including a reentrancy issue that allowed recursive calls to the contract, let's explore an example of reentrancy in Ethereum smart contracts.

  2. Reentrancy

    Lab40m

    Let’s head to the lab to discover, debug, and fix this vulnerability within an actual application.

  3. Lessons Learnt

    Lesson10m

    Ethereum smart contracts function like public banks where transactions are visible, and defensive programming is essential to address various vulnerabilities, including both new and old ones.